Skip to main content

Compliance Engine v1

Cloudaware Compliance Engine (v1) is the control plane for continuous cloud governance and technical compliance. Compliance Engine evaluates your cloud and on‑prem resources discovered in Cloudaware CMDB against industry benchmarks and custom policies, produces evidence as structured findings, and orchestrates routing and remediation.

info
  • Audience: Security and compliance teams, cloud and platform teams, auditors, and risk owners
  • Outcome: Continuous compliance assessment with policy findings, evidence, remediation workflows, dashboards, and audit-ready reporting across cloud and on-prem environments

Use Compliance Engine when you want to:

  • Standardize on benchmark‑driven controls across AWS, Azure, GCP, and on‑prem.
  • Implement Cloudaware‑authored and custom policies aligned to your internal standards and/or external frameworks (PCI, HIPAA, NIST, ISO, GDPR, and others).
  • Continuously monitor environments, detect violations, and measure how quickly issues are resolved.
  • Produce audit‑ready evidence and reports without rebuilding spreadsheets before every review.
  • Integrate compliance findings into ITSM, collaboration, and SIEM/SOAR tooling.
note

This section documents Compliance Engine v1 (legacy). For Compliance Engine v2, see this documentation.

Core Capabilities

Cloudaware Compliance Engine v1 provides:

  • Benchmark-based assessment – supported resources evaluated against predefined control packs such as CIS benchmarks for AWS, Microsoft Azure, and Google Cloud.
  • Cloudaware‑authored controls – policy coverage for security, reliability, operational excellence, and cost-related configuration risks.
  • Custom policy development – organization-specific controls implemented with Cloudaware's Salesforce-based policy language.
  • CMDB-based scoping – evaluations targeted using resource type, ownership, application, environment, account, tags, and relationships.
  • Structured findings and evidence – persistent output records used for investigation, reporting, audit support, and downstream workflows.
  • Violation routing and remediation – findings directed to owners, Jira, ServiceNow, automation, and other connected tools.
  • Exception and risk management – approved exclusions, risk acceptance, ownership, expiration, and review workflows associated with findings.
  • Dashboards and reporting – posture, trends, remediation progress, exception aging, and audit evidence available through reports, dashboards, alerts, and exports.

How Compliance Engine Works

Compliance Engine v1 follows a CMDB-based evaluation workflow:

  1. Identifies in-scope assets. Cloudaware CMDB provides resources, ownership, tags, relationships, applications, and environment context.
  2. Applies policies and policy packs. Policies define the expected state for specific CMDB object types. Policy packs group related controls, such as CIS benchmarks, for deployment and management.
  3. Runs evaluations. Evaluation jobs execute policies against in-scope assets on a schedule or on demand.
  4. Creates findings and output objects. Each evaluation produces persistent records describing the result for the evaluated asset.
  5. Routes violations and exceptions. Findings can trigger notifications, tickets, approval processes, automation, remediation, or risk-acceptance workflows.
  6. Surfaces posture and evidence. Dashboards, reports, KPIs, alerts, and exports provide compliance status, trends, ownership, and remediation information.

Because evaluation scope is based on CMDB context, policies can follow business structures such as applications, teams, environments, and ownership groups rather than relying only on cloud account boundaries.

Compliance Engine Building Blocks

  • Policy Packs – curated sets of controls (for example, CIS benchmarks) that can be enabled and scoped as a group.
  • Policies – individual controls that target a CMDB object type (for example, AWS Account, EC2 Instance, S3 Bucket) and express compliance logic.
  • Evaluations – jobs that execute policies across in‑scope assets on a cadence or on demand.
  • Findings/Output Objects – persistent records that represent the state of each asset with respect to a policy (compliant, incompliant, inapplicable).
  • Remediation & Exceptions – workflows, ticketing, automations, and risk‑acceptance processes that close the loop.
  • Reporting & Dashboards – visualization of posture, trends, remediation velocity, and exception aging.

Relationship to Other Modules

Compliance Engine works closely with other Cloudaware modules:

  • CMDB provides inventory, relationships, and ownership context.
  • Backup & Replication can use Compliance Engine findings to identify backup-related misconfigurations, such as missing backups or insufficient retention periods, so teams can incorporate those findings into backup review and remediation workflows.
  • Cost Management can highlight the cost impact of non‑compliant resources and remediation choices.

Treat Compliance Engine as the source of truth for control posture and evidence, with other modules supplying inventory, enforcement actions, monitoring, and cost visibility.

Explore the Compliance Engine v1 Documentation

Use these guides together as the Cloudaware Compliance Engine (v1) documentation set.

Prepare Compliance Engine

  1. Review requirements. Confirm prerequisites for CMDB data, cloud integrations, licensing, RBAC, connectivity, and expected scale.

  2. Review policy packs. Understand benchmark packs, Cloudaware-authored control collections, and custom deployable groups.

  3. Understand policies. Review policy structure, deployment, revisions, utility classes, and status transitions.

Evaluate Resources

Remediate and Integrate

  • Remediation & Workflows: Configure tickets, automation, exceptions, risk acceptance, and remediation processes.
  • Integrations: Connect findings to ITSM, collaboration, SIEM, SOAR, automation, and evidence-storage platforms.

Report and Operate

  • Reporting & Dashboards: Build KPIs, dashboards, scheduled reports, email alerts, and audit evidence views.
  • Operations: Manage RBAC, data governance, performance, scale, and recurring operational tasks.
  • Playbooks: Follow practical workflows for baseline rollout, priority remediation, and audit preparation.
  • Reference: Review policy language, finding schemas, limits & quotas.
  • FAQ: Find answers about controls, scope, evaluation cadence, finding statuses, exceptions, and workflows.